Sign inSign up
PostgreSQL

dhi.io/postgres

PostgreSQL 18.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

18-alpine-fips-dev, 18-alpine3.24-fips-dev, 18.6-alpine-fips-dev, 18.6-alpine3.24-fips-dev

Index digest:

sha256:96987a80ec067f38209c2d1bc89107b203c06f4d964c5cfcf2eda2698752bcd5

Manifest digest:

sha256:50691602030318a57171642101fd8a5370e9f6bdb33e0eac8a33e08dde3d023c

Size

151.45 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Nov 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/postgres:18-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/postgres:18-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/postgres@sha256:0c4abd8cfb2cf852672650f45731448197714350dcf14c8cb45240130600f7b9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/postgres@sha256:d2b86bcee94a29b98a24330a1d4c5bf7f0ff998df1013dd0192c2018bf5dd6b8
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/postgres@sha256:a868cb2565e4838000f1a85b6897b9d3c3f4ede6df68f599f28d7ec9bfe75a11
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/postgres@sha256:7f11985c5396e7144cccd76c3644212e577d69f5a6bebe65090148fb19b7bf44
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/postgres@sha256:e7b6d6c29be08395b90612a9693eefe068c9d080af3569a8d0c42d5bbf6af646
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/postgres@sha256:5bfe26180fd41de1a2cd5cae45c643b6b5cd63310ddb9e368a624659242cb01c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/postgres@sha256:50f026707c347fa7c799f2914301aca10f0f42709be41132868e5a24f425e2bc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/postgres@sha256:76fe170261a90c01cc5a15279325e8cf923f34e7f753b499f2160de7790d68d5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/postgres@sha256:3c4a891a60c4980fda3b6da6e3284f06f52fd080118d3d6a50a8f48a5df7f513
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/postgres@sha256:2203858fd57a5b38a6a58b2f09996d166584310238a0c2b1ebc3d3f7699b90e5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/postgres@sha256:76167093796c72bf5e358f425cd621ec79256cd90727048813d9bb9d6855a9bb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/postgres@sha256:735e0a1abe38785d2e99d201f794ce53134543493a771763006d2e65b04bace7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/postgres@sha256:9dad42bcfa67912618a3c9e3a3d5ce4894f6e0faae8221a91dff52c885e49465
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/postgres@sha256:03de50e367fc03502291baeb1b4f8bde70152872ce2ba9e73210ded380dcb483
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/postgres@sha256:9beae35c79b0f72640d5377410a9e9ff256a6b1496b02719bf40b14f276717f6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/postgres@sha256:e0c74305fe6f9039825f5dcccd6e2160e2b549f019274b42025ccfde6be11578